PatchSiren

alexpechkarev CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL alexpechkarev CVE published 2026-10-04

CVE-2026-105222

The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default. This vulnerability allows on-path attackers to intercept Google Maps web-service requests, potentially leading to the theft of API keys and tampering with responses. The vulnerability arises from the bundled configuration setting ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. [truncated]